Application Security News and Articles


‘Microsoft’ Scammers Steal the Most, says FTC

Pork Talk: “Pig butchering” scams are on the rise via social media. The post ‘Microsoft’ Scammers Steal the Most, says FTC appeared first on Security Boulevard.

The Rise of Generative AI is Transforming Threat Intelligence – Five Trends to Watch

As threats increase in sophistication—in many cases powered by GenAI itself—GenAI will play a growing role in combatting them. The post The Rise of Generative AI is Transforming Threat Intelligence – Five Trends to Watch appeared first on ...

HP Report Surfaces Shifts in Cyber Attack Tactics

Cyber attack tactics are evolving, according to a new report, from advanced campaigns to exploiting weaknesses, and cybersecurity teams should be optimally employed. The post HP Report Surfaces Shifts in Cyber Attack Tactics appeared first on ...

Kasada Achieves 2024 Great Place to Work® Certification for Second Consecutive Year

Company celebrated for outstanding U.S. workplace environment The post Kasada Achieves 2024 Great Place to Work® Certification for Second Consecutive Year appeared first on Security Boulevard.

Writing Burp extensions in Kotlin

Learn how to write Burp Suite extensions using the new Montoya API with Kotlin and Visual Studio Code (VS Code) The post Writing Burp extensions in Kotlin appeared first on Dana Epp's Blog. The post Writing Burp extensions in Kotlin appeared ...

USENIX Security ’23 – Generative Intrusion Detection and Prevention on Data Stream

Authors/Presenters: HyungBin Seo, MyungKeun Yoon Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s ...

Threats of the Week: Black Basta, Scattered Spider, and FIN7 Malvertising

The only way that we can help our community and our enterprise customers continue to check their coverage against adversary activity and new threats is to keep our platforms fresh. In the last week, the Tidal Cyber Adversary Intelligence Team ...

Tonic Textual extracts, governs, and deploys unstructured data for AI development

Tonic.ai launched secure data lakehouse for LLMs, Tonic Textual, to enable AI developers to seamlessly and securely leverage unstructured data for retrieval-augmented generation (RAG) systems and large language model (LLM) fine-tuning. Tonic ...

User Guide: PCI 4.0 Requirement 11.6 – Detecting and Responding to Unauthorized Changes on Payment Pages with Feroot

Protecting your e-commerce platform from unauthorized changes and skimming attacks is paramount for maintaining trust and ensuring compliance with PCI DSS 4.0, specifically requirement 11.6. This guide will walk you through utilizing Feroot ...

RSAC Fireside Chat: Dispersive adapts WWII radio-signal masking tool to obfuscating network traffic

Spread spectrum technology helped prevent the jamming of WWII radio-controlled torpedoes and subsequently became a cornerstone of modern-day telecom infrastructure. For its next act, could spread spectrum undergird digital resiliency? I had an ...

Fred Burton’s 2024 Summer Reading List

Protectors read books, while travelling, in airports, follow-cars, hotel rooms, or during down time in GSOCs. We especially love a good thriller in our industry, along with thought provoking non-fiction. With that in mind, here are a few perfect ...

INE Security Enables CISOs to Secure Board Support for Cybersecurity Training

Cary, United States, 28th May 2024, CyberNewsWire The post INE Security Enables CISOs to Secure Board Support for Cybersecurity Training appeared first on Security Boulevard.

Adaptive Shield unveils platform enhancements to improve SaaS security

To secure emerging SaaS attack surfaces, Adaptive Shield has extended the capabilities of its SaaS Security Posture Management (SSPM) unified platform to cover complex Permissions and Shared Data. “SaaS security impacts the entire organization, ...

I Failed a Pentest: What do I Do?

Steps you should take after failing a pentest and focusing on addressing the vulnerabilities found and ensuring there are no compromises. The post I Failed a Pentest: What do I Do? appeared first on Security Boulevard.

The Link Between Cybersecurity and Reputation Management for Executives

The link between cybersecurity and personal reputation management for executives is significant. As leaders in their respective fields, executives are often the face of their company’s brand, and are responsible for maintaining the trust of ...

Attackers are probing Check Point Remote Access VPN devices

Attackers are trying to gain access to Check Point VPN devices via local accounts protected only by passwords, the company has warned on Monday. Their ultimate goal is to use that access to discover and pivot to other enterprise assets and users, ...

Vendor Risk Management Best Practices in 2024

How do you keep tabs on your vendors without draining resources? Here’s our list of best practices for vendor risk management.  The post Vendor Risk Management Best Practices in 2024 appeared first on Scytale. The post Vendor Risk Management ...

Black Basta Ransomware Attack: Microsoft Quick Assist Flaw

Recent reports claim that the Microsoft Threat Intelligence team stated that a cybercriminal group, identified as Storm-1811, has been exploiting Microsoft’s Quick Assist tool in a series of social engineering attacks. This group is known for ...

The evolution of security metrics for NIST CSF 2.0

CISOs have long been spreadsheet aficionados, soaking up metrics and using them as KPIs for security progress. These metrics have traditionally measured specific systems or single indicators — vulnerabilities detected, percentage of ...

How to combat alert fatigue in cybersecurity

In this Help Net Security interview, Ken Gramley, CEO at Stamus Networks, discusses the primary causes of alert fatigue in cybersecurity and DevOps environments. Alert fatigue results from the overwhelming volume of event data generated by ...